← Back

Cloud Services Appliance

cloud_services_appliance

Vendor: Ivanti • 7 CVEs

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ivanti
1Cloud Services Appliance
Jul 16, 2025
May 13, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privileges.
1Ivanti
1Cloud Services Appliance
Feb 20, 2025
Feb 11, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
1Ivanti
1Cloud Services Appliance
Jul 14, 2025
Feb 11, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Path traversal in Ivanti CSA before version 5.0.5 allows a remote unauthenticated attacker to access restricted functionality.
1Ivanti
1Cloud Services Appliance
Jan 17, 2025
Dec 10, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
1Ivanti
1Cloud Services Appliance
Jan 17, 2025
Dec 10, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
1Ivanti
1Cloud Services Appliance
Jan 17, 2025
Dec 10, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access
1Ivanti
1Cloud Services Appliance
Oct 24, 2025
Sep 10, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privil...Show more
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.Show less